my timesThe Korea Times

N. Korean, Chinese hackers grow bolder, target crypto, nuclear sites

Listen
gettyimagesbank

gettyimagesbank

Hackers backed by North Korea and China are escalating global cyberattacks, infiltrating hundreds of organizations across government, education and critical infrastructure — including leading cryptocurrency platforms and the U.S. agency responsible for nuclear weapons, cybersecurity experts reported.

Dutch cybersecurity firm Eye Security reported that more than 400 institutions worldwide have been breached in recent days. Most of the victims are based in the United States, with additional incidents reported in Mauritius, Jordan, South Africa, the Netherlands and other parts of Europe, Asia, the Middle East and South America.

This expansive and unconstrained campaign signals a worrying new phase in the North's state-sponsored cyber warfare, demonstrating both a heightened capability and a broader intent to destabilize critical sectors far beyond traditional intelligence gathering. The global reach of these incursions underscores the severe and interconnected vulnerabilities facing both public and private entities worldwide.

The attacks are still unfolding, with hackers actively scanning and exploiting vulnerable servers. Security analysts say the real extent of the damage is likely far greater than currently known.

Among the most serious breaches was at the National Nuclear Security Administration (NNSA), the U.S. Department of Energy agency tasked with managing the nation’s nuclear weapons stockpile. The NNSA also oversees nuclear propulsion for the Navy and responds to nuclear and radiological emergencies.

Beginning July 18, attackers exploited a previously unknown vulnerability in Microsoft SharePoint, the Energy Department said. While only a small number of systems were reportedly affected, the breach has raised concerns about the cybersecurity of some of the U.S. government’s most sensitive operations. Officials added that reliance on Microsoft’s cloud-based systems and robust internal defenses helped contain the incident.

Microsoft attributed the broader campaign to China-based state-sponsored hackers, who are believed to be behind a coordinated operation targeting multiple public institutions. Other affected entities reportedly include the U.S. Department of Education, the Florida Department of Revenue, the Rhode Island state legislature and various agencies across Europe and the Middle East.

At the same time, North Korean-linked hacking groups have resumed large-scale thefts of cryptocurrency, reversing a slowdown seen in 2024.

In just the first half of 2025, North Korean hackers are believed to have stolen $2.17 billion in cryptocurrency — already surpassing losses recorded in the first half of 2022, previously the worst year on record.

A single incident — the theft of $1.5 billion from crypto exchange Bybit — accounted for the bulk of these losses. Analysts believe the breach involved advanced social engineering techniques, with North Korean IT workers potentially infiltrating crypto firms under false identities.

North Korea had stolen $1.3 billion in crypto in 2024, but the sharp increase this year reflects a renewed focus on illicit cyber activities as a critical source of funding for the regime. The combination of traditional cyber espionage targeting national security systems and aggressive financial crimes underscores the widening scope and impact of state-sponsored hacking campaigns.

Security experts warn that these coordinated attacks — spanning continents and industries — highlight an urgent need for global cooperation to bolster cyber defenses and respond to the growing threat from North Korean and Chinese cyber actors.